Please do not report security vulnerabilities through public GitHub issues.
Use GitHub’s private vulnerability reporting (Security → Report a vulnerability) or submit a report directly at:
https://github.com/trydrift/drift/security/advisories/new
If possible, include:
- the affected Drift surface (CLI, GitHub Action, webhook server, or VS Code extension) and version or commit;
- the security boundary you believe can be bypassed;
- reproduction steps;
- the impact you believe is possible.
We aim to acknowledge vulnerability reports within 7 days and coordinate disclosure with the reporter.
We generally target disclosure within 90 days, depending on severity and remediation complexity.
Please do not publicly disclose a vulnerability before we have had a reasonable opportunity to investigate and address it.
See docs/trust-and-safety.md for the threat model Drift documents against itself.